SOC analysts, blue-team practitioners, incident responders, threat hunters and cybersecurity students who already understand security operations.
Entry requirements
Read endpoint, network and identity logs; understand incident triage, TCP/IP and basic SIEM queries. Basic Python editing helps with workflow labs. This is not an entry-level networking course.
Weekly commitment
Allow 3–5 independent practice hours each week. Live time totals 36–54 hours across 36 sessions; assignments and preparation do not count toward those hours.
Recommended planning baseline: a laptop with 16 GB RAM, 30 GB free disk space, reliable internet and permission to install the agreed local lab tools. Confirm the actual cohort setup before buying equipment. A GPU is not assumed; heavier models may need an approved hosted endpoint with separate usage charges.
WEEK-BY-WEEK CURRICULUM
Learn through security work.
Each week combines explanation, guided practice and evidence review across three sessions. The lab tasks and portfolio outputs below form the assessment trail.
WEEK 1–2
Verified AI analyst workflows
LLM limits, redaction, evidence grounding, security telemetry and prompt-injection risks inside logs and threat reports.
Lab: Compare manual and AI-assisted triage on labelled cases; test adversarial text embedded in synthetic logs.
Evidence: Evidence checklist and triage baseline.
WEEK 3–4
SOC triage and detection engineering
Wazuh workflows, asset and identity context, Sigma drafting, anomaly scores, false positives, precision/recall and rule tuning.
Lab: Build and test an enrichment workflow and detection rules using benign controls and attack replay data.
Evidence: Casebook, validated rules and detection scorecard.
WEEK 5–6
Threat intelligence and hunting
ATT&CK mapping, confidence in intelligence, IOC validation, hunt hypotheses, query safety and lateral-movement evidence.
Lab: Investigate a multi-stage synthetic intrusion and distinguish useful indicators from misleading matches.
Evidence: Hunt notebook, evidence trail and coverage gaps.
Map threats and controls, justify test scope and trace evidence. These are references, not software subscriptions or AI5 accreditations.
Demonstrated or evidence-led
Cloud-native AI controls, enterprise SOC copilots and larger model attack scenarios
Instructor walkthroughs or sanitized evidence packs; not every platform is a student lab.
Commercial / usage-dependent
Microsoft Security Copilot, Sentinel, Splunk, enterprise AI assistants, cloud accounts and paid model APIs
Hands-on access only when a suitable license, tenant and budget are confirmed. These subscriptions, credits and exams are not automatically included. Equivalent local exercises support the core learning goals.
Use only approved AI endpoints with synthetic or sanitized data. Product names describe training context, not partnerships. Tool versions and the exact lab access list are confirmed for each cohort.
ASSESS THE WORK, NOT THE PROMPT
Portfolio and employer-grade capstone
SOC triage copilot with citations
ATT&CK hunt and Sigma pack
Cloud incident timeline
Approval-gated response workflow
Final capstone
Deliver an AI-assisted SOC investigation pack for a simulated company: tested detections, a documented intrusion timeline, scope and uncertainty, approved response decisions, recovery checks and an executive incident brief.
40% · Practical evidence
Reproducible results, source checks, tested controls and useful lab records.
20% · Scenario decisions
Range performance, uncertainty, approval boundaries and communication.
40% · Capstone & defence
Working or auditable deliverables, unseen test cases, handover and individual explanation.
Completion standard: 70% overall, all mandatory submissions and a pass on evidence verification and authorization controls. Unsafe unapproved actions or fabricated evidence must be corrected and reassessed. AI assistance must be disclosed; copied model output without verification is not accepted as proof.
Technical scorecards include false positives, detection or attack-success measures, clean-task performance and reproducibility. Governance scorecards check evidence completeness, control ownership, risk decisions and traceability. An attractive report alone does not meet the standard.
PRACTISE THE WHOLE DECISION
Cyber Range: investigate, verify, respond.
The Cyber Range is a sequence of isolated training scenarios using local applications, synthetic company records and replayed security events. Technical routes test controls; the governance route reviews the evidence and authorizes decisions in tabletop exercises.
Investigate
Work with incomplete evidence, noisy alerts and an AI system that can make mistakes. Record hypotheses and competing explanations.
Verify
Reproduce findings, test benign controls and keep source references, timestamps, configuration and version records.
Respond
Request approval for changes, test containment and rollback, then explain remaining risk in an operational handover.
All testing stays within authorized training targets. No live third-party attacks or real customer secrets. Hosted range subscriptions and continuous access are not assumed; confirm the cohort’s delivery and access arrangements before enrolment.
BUILT TO KEEP LEARNING
AI5 Emerging Threat Lab
Each cohort examines a recent AI-security advisory or research finding within its scheduled lab time. Learners check the source, assess relevance, reproduce a safe bounded example where feasible, test a mitigation and add an evidence-backed advisory to their portfolio.
Topics may include new agent protocols, AI-to-AI trust failures, memory poisoning, impersonation, autonomous tool misuse or changes in defensive models. This prepares learners for increasingly capable AI without speculative claims about AGI. The lab refreshes case material while preserving the program’s core learning outcomes and hours.
Live Online. Built for professional teams worldwide.
English-language live instruction, practical assignments and individual review. International learners should share their country and time zone so admissions can confirm a suitable cohort, local class times and daylight-saving changes before enrolment. Three sessions per week; generally 60–90 minutes each.
AI5 also serves learners in India and Delhi NCR. These programs are listed as Live Online; any on-site company delivery requires a separate agreed scope. Ask for batch dates, fees, applicable taxes, payment currency and international payment instructions. No batch date or commercial-tool access is promised until confirmed.
Companies can request a private cohort around approved tools, sanitized scenarios, team roles and measurable acceptance criteria. Discuss company training.
Questions before you join
How is this different from a conventional cybersecurity course?
AI-assisted security work and the security of AI systems are the starting point. Every workflow requires evidence checks, explicit authority and measurable tests. Conventional foundations are prerequisites or targeted refreshers, rather than the main curriculum.
How many live sessions and hours are included?
12 weeks × 3 sessions = 36 live sessions. At 60–90 minutes each, that is 36–54 instructor-led hours. Independent assignments are additional.
Do I need coding or cybersecurity experience?
Read endpoint, network and identity logs; understand incident triage, TCP/IP and basic SIEM queries. Basic Python editing helps with workflow labs. This is not an entry-level networking course.
Are paid tools, exams or professional certifications included?
Do not assume a commercial subscription, cloud credit, vendor exam, external certification or CPE entitlement is included. Core practical work uses local/open tools and synthetic evidence where possible. Ask admissions for a written list of any batch-specific access costs and completion documentation.
Can international learners and company teams join?
Yes, through Live Online training in English, subject to a suitable confirmed cohort. Share your time zone and objectives. Companies may request a private cohort with agreed tools and sanitized scenarios.
Does the program guarantee a job or a secure AI system?
No. The assessed output is a portfolio of verified workflows and control evidence. Hiring and production security depend on experience, the environment and ongoing review; a course or scanner cannot guarantee either.
CURRICULUM REFERENCES
Work from current security guidance.
Source pages checked September 2026. Each cohort records the editions, tool versions and advisories used in its lab briefs. Framework use does not imply accreditation, partnership or endorsement.